back to live missions analysis

Deepfake fraud: what the adjudicated record actually shows in 2026

2026-09-06

The biggest deepfake fraud numbers are victim-reported or projected. What an independent regulator and a court have actually put on record is smaller, specific, and more useful.

Built on verified case files. The argument below leans on evidence The Internet Ninja validated against the public record and published in full, method included.

The number you have seen is 25 million dollars: the sum an Arup finance employee wired out after a video call where the CFO and colleagues on screen were all AI-generated source. It is a real case and a good warning. It is also a figure the victim reported and no independent body has adjudicated.

That is the pattern under almost every deepfake fraud statistic. The headline losses are reported by the party that lost the money, or projected by a firm that sells the defence. Both can be honest and still be unverified.

So this post does the opposite of the usual roundup. It sets the loud, reported numbers next to the small set of cases where an outside authority actually put deepfake harm on the record, and asks which one you should build a control on.

What deepfake fraud means

Deepfake fraud is a scam that uses AI-synthesised audio, video, or images of a real person to impersonate them and authorise a payment, a login, or a decision. The deepfake is the credibility, not the theft: it makes a request the target would normally question sound like it came from someone they trust.

How big is deepfake fraud in banking

The honest answer is that the totals are estimates, not counts. Deloitte’s Center for Financial Services projects that generative-AI-enabled fraud losses in the United States “could reach US$40 billion in the United States by 2027, from US$12.3 billion in 2023, a compound annual growth rate of 32%” source.

Read what that is. It is a projection to a future year, built from a 2023 baseline, covering deepfakes alongside synthetic identities and automated social engineering. It is useful for sizing a risk. It is not a tally of adjudicated losses, and it should never be quoted as one.

Deepfake fraud examples

The clearest documented example is Arup. A staff member in Hong Kong made a number of transfers to five bank accounts after a video conference in which the other participants were AI-generated likenesses of real executives; Hong Kong police reported the case in February 2024 and the firm was named that May source. The loss, about 25 million dollars, is the company’s own account relayed through the press, not a court finding.

That is the ceiling of what most examples give you: a credible story, a large number, and no independent adjudication of the figure. It is exactly the kind of claim TIN exists to separate from proof.

Deepfake vs cheap fake

A deepfake is media generated or heavily synthesised by an AI model: a cloned voice, a swapped face, a fabricated video. A cheap fake is authentic media altered by hand: a clip slowed down, mislabelled, or spliced. The distinction matters for detection, because a cheap fake defeats a deepfake detector by not being synthetic at all. For the victim, the fraud lands the same way, through a message that looks like it came from someone real.

The proof: what the adjudicated record shows

TIN audits the public record rather than incident reports, and here the record is narrow but firm. Neither of TIN’s two verified cases is a bank-transfer scam. Both are cases where an independent authority put a number, or a cost, on synthetic media, which is precisely what the reported-loss statistics lack.

The first is the FCC’s 1 million dollar settlement with Lingo Telecom, the carrier that transmitted AI-voice-cloned robocalls impersonating President Biden to tell New Hampshire voters to stay home. The FCC found Lingo had applied “an A-level attestation, which is the highest level of trust attributed to a phone number”, to calls whose number was spoofed source. The lesson sits in the remedy: the defence the regulator demanded was verified caller provenance, not better fake-audio detection.

The second is Kohls v. Ellison, where a federal judge excluded a misinformation expert’s declaration in a case about deepfakes, after GPT-4o “provided Professor Hancock with fake citations to academic articles, which Professor Hancock failed to verify before including them in his declaration” source. No fine was imposed; the synthetic content cost the state its evidence. It is the same failure as a deepfake fraud, one step upstream: trusting AI output nobody checked.

The record, side by side

ClaimWhat it saysWho says itIndependently adjudicated
Arup lossAbout 25 million dollars wired after a deepfake video callThe victim firm, via pressNo
Deloitte projectionUp to 40 billion dollars in US gen-AI fraud by 2027A firm selling fraud defenceNo, it is a forecast
FCC / Lingo Telecom1 million dollar penalty for carrying AI deepfake robocallsUS regulator (FCC)Yes
Kohls v. EllisonAI-fabricated citations excluded, evidence lostUS federal courtYes

Read the right-hand column. The two rows an outside authority stands behind are smaller and narrower than the headline losses, and they are the two you can build a control on without taking a vendor’s or a victim’s word for the size of the problem.

The bottom line

Deepfake fraud is real, and the reported losses are probably conservative. But a projection is not a measurement and a victim’s account is not an audit, and treating either as fact is how a risk gets mispriced in both directions. The adjudicated record is thinner, and it points somewhere specific: in every case an authority has actually ruled on, the defence that held up was verified provenance, knowing the voice or the citation was genuine before acting on it, not a detector trained to spot the fake after the fact. That rule outlives the current models. When the synthesis gets good enough that detection fails, the only thing left standing is whether you verified the source. TIN’s separate read on why detection loses that race is in why AI watermark detection fails and verification works, and the same reported-versus-adjudicated split runs through what the documented record shows on AI fraud detection.

Sources

  1. CFO Dive, “Scammers siphon $25M from engineering firm Arup via AI deepfake ‘CFO’”, 2024-05-17. https://www.cfodive.com/news/scammers-siphon-25m-engineering-firm-arup-deepfake-cfo-ai/716501/
  2. Deloitte Center for Financial Services, “Generative AI is expected to magnify the risk of deepfakes and other fraud in banking”, 2024-05-29. https://www.deloitte.com/us/en/insights/industry/financial-services/deepfake-banking-fraud-risk-on-the-rise.html
  3. U.S. Federal Communications Commission, “FCC Settles Case Against Provider That Transmitted Spoofed AI-Generated Robocalls For Election Interference In New Hampshire”, 2024-08-21. https://docs.fcc.gov/public/attachments/DOC-404951A1.pdf
  4. U.S. District Court, D. Minnesota, “Order in Kohls v. Ellison, No. 24-cv-3754 (LMP/DLM), Document 46”, 2025-01-10. https://www.courtlistener.com/docket/69206960/kohls-v-ellison/

Questions

What is deepfake fraud?

Deepfake fraud is a scam that uses AI-generated audio, video, or images of a real person to impersonate them and authorise a payment or decision. The best-known example is a finance employee at engineering firm Arup who transferred about 25 million dollars after a video call in which every other participant was a deepfake.

How big is deepfake fraud in banking?

Nobody knows precisely, because most figures are estimates. Deloitte's Center for Financial Services projects that generative-AI-enabled fraud losses in the United States could reach 40 billion dollars by 2027, up from 12.3 billion dollars in 2023, a projection rather than a measured total.

What is the difference between a deepfake and a cheap fake?

A deepfake is media synthesised by a generative-AI model, such as a cloned voice or a face swapped onto a video. A cheap fake is real media altered with simple edits, such as slowing a clip or relabelling it. The fraud risk is the same; only the tooling differs.

Has anyone been penalised for deepfake fraud?

Yes, on the enabling side. The FCC settled with the carrier that transmitted the AI Biden deepfake robocalls for a 1 million dollar civil penalty in 2024, and a federal court excluded an expert declaration in 2025 after AI invented its citations. Both are adjudicated, unlike most reported loss figures.

Sources

  1. CFO Dive, Scammers siphon $25M from engineering firm Arup via AI deepfake 'CFO' , 2024-05-17
  2. Deloitte Center for Financial Services, Generative AI is expected to magnify the risk of deepfakes and other fraud in banking , 2024-05-29
  3. U.S. Federal Communications Commission, FCC Settles Case Against Provider That Transmitted Spoofed AI-Generated Robocalls For Election Interference In New Hampshire , 2024-08-21
  4. U.S. District Court, D. Minnesota, Order in Kohls v. Ellison, No. 24-cv-3754 (LMP/DLM), Document 46 , 2025-01-10